fix(nginx+compose): dotfile block first, no pdf gzip, single healthcheck (tour J4/N4/J5)
Dotfile location moved above caching regex locations (first match wins). application/pdf out of gzip_types (already flate-compressed). Compose healthcheck block removed — image HEALTHCHECK is the single source, inherited. Oracles: nginx -t, dotfiles 404, PDF no Content-Encoding, HTML still gzipped, headers 5/5, inherited health = healthy.
This commit is contained in:
+7
-6
@@ -36,9 +36,15 @@ server {
|
||||
application/javascript
|
||||
application/json
|
||||
application/xml
|
||||
application/pdf
|
||||
image/svg+xml;
|
||||
|
||||
# Block access to dotfiles (defense-in-depth — none are shipped anyway).
|
||||
# First regex location wins: keep this above the caching regex blocks so
|
||||
# a hypothetical /.foo.html can't be served by them.
|
||||
location ~ /\. {
|
||||
return 404;
|
||||
}
|
||||
|
||||
# Long cache for the PDF (regenerated rarely, content-hash not used).
|
||||
location ~* \.pdf$ {
|
||||
add_header Cache-Control "public, max-age=604800";
|
||||
@@ -62,11 +68,6 @@ server {
|
||||
access_log /var/log/nginx/access.log;
|
||||
error_log /var/log/nginx/error.log warn;
|
||||
|
||||
# Block access to dotfiles (defense-in-depth — none are shipped anyway).
|
||||
location ~ /\. {
|
||||
return 404;
|
||||
}
|
||||
|
||||
# Default: serve files, fall back to 404.
|
||||
location / {
|
||||
try_files $uri $uri/ =404;
|
||||
|
||||
Reference in New Issue
Block a user